ComputerWeekly

NCSC and pals call out company that backed Chinese state hackers


The UK’s National Cyber Security Centre (NCSC) has joined its Five Eyes partners from Australia, Canada, New Zealand and the US, and counterpart cyber agencies from Japan and Spain, to reveal how a supposedly legitimate technology business is brazenly acting as a front for Chinese cyber spooks.

In a joint advisory published today, the NCSC accused the Integrity Technology Group already-sanctioned Integrity Technology Group – a China based cyber security software supplier – of enabling state-backed threat actors to target western organisations using AI-enabled tools, large-scale botnets, and hands-on exploitation techniques to compromise networks and steal data on behalf of Beijing.

The advisory details how Integrity employs individuals to support a range of malicious cyber activities, including developing tools for use and sale, and acquiring and hosting infrastructure. The activity supported by Integrity appears to be consistent with campaigns run by advanced persistent threat (APT) groups such as Flax Typhoon, also known as Ethereal Panda and Red Juliett.

“The extensive malicious cyber activities, and services by Integrity Tech, that have been exposed today should be extremely concerning for all network defenders,” said NCSC operations director Paul Chichester.

“The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organisations should take note of this warning and engage with NCSC advice and guidance.

“We will continue to call out malicious actors and the malevolent ecosystem they operate in,” said Chichester.

Well-known threat

Integrity Technology Group has been a thorn in the side of western security agencies for some time.

Back in 2024, it was exposed as the operator of a malicious Mirai botnet composed of hijacked internet of things (IoT) devices that Flax Typhoon used in cyber attacks against western targets. Of the 250,000 total compromised devices that comprised the botnet, approximately 8,500 were physically located in the UK.

Then, towards the end of 2025, Integrity – along with another company known as Sichuan Anxun Information Technology Co Ltd – found itself sanctioned amid accusations of involvement in 80 cyber attacks, some of them against British public sector targets.

Americans seize hacking tools

At the same time, the US Department of Justice (DoJ) and the Federal Bureau of Investigation (FBI) announced a series of court-authorised domain seizures intended to deny Integrity access to two hacking tools known as Microscan and FishHub.

Integrity is accused of operating these tools against operators of critical national infrastructure (CNI) in the US , according to court documents unsealed in the Western District of Pennsylvania.

“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said FBI Cyber Division assistant director Brett Leatherman.

“The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”

The Americans accused Integrity of operating another Mirai botnet to conduct vulnerability scanning and reconnaissance using Microscan, with targets including a South Carolina-based electricity company, a multinational non-governmental organisation (NGO), airports in Japan and Poland, and Taiwanese universities and CNI operators.

FishHub, meanwhile, was allegedly used by Integrity to download malware to its victims’ networks after having compromised them in spear-phishing attacks, and access and exfiltrate sensitive data. Confirmed FishHub victims include multiple academic institutions in Taiwan.

Next steps

The advisory – which can be downloaded here – details a number of common vulnerabilities and exposures (CVEs), some of them dating back to the mid-2010s, that Integrity has been taking advantage of, primarily by using scanning tools, cross-site scripting (XSS) attacks, and password spraying against unpatched Microsoft Exchange servers.

Defenders are advised to take the following key actions. First, unused services and ports such as automatic configuration, remote access, or file sharing protocols, should be disabled. Second, user input in web apps should be sanitized to prevent possible XSS payload injection. Third, identity and access management (IAM) policies should be audited and implemented, and multifactor authentication (MFA) enabled to the fullest extent possible.

Nick Hann, field chief technology officer (CTO) at Claroty, said: “Manufacturers and healthcare providers need to take this threat seriously, as the latest advisory names them as specifically targeted sectors.

“These actors use password spraying and covert VPN connections to steal credentials and email, but once inside, they could reach the systems keeping factories running and patients safe. Getting that far would turn a data breach into stalled production lines, broken supply chains and delayed patient care.”

Hann said that Integrity’s success with older flaws demonstrated how legacy technology continues to be a weak point, particularly in industrial and clinical environments where devices can remain in service for many years.



Source link